This is worthy of a paper, Twitter not sufficient. I imagine blocking 306 million pwds would cause massive customer loss & complaints.
All that stuff applies to enterprise systems, banks, etc. Your average modern Web company has no problem w/min=12 *if* it doesn't lose users
-
-
So why aren't Twitter, Google, Facebook, and every mildly popular web startup using min=12 when it's a trivial config change for them?
-
Because they prefer good UX, does risk analysis and threat models, and have TONS of compensating controls instead. Good security UX.
- Show replies
New conversation -
-
-
1) Poland: LAW requires pwds protecting personal info to be min 6 characters, and change every 30 days. Frequent chsnge make security bad.
-
2) applies to everyone afaik. I'm not talking single, modern, small web shop with good admits Herr.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.